2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3164 | HIGH | 8.8 | 4.2% | Jan 26, 2021 | ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permis... |
| CVE-2021-3152 | MEDIUM | 5.3 | 2.2% | Jan 26, 2021 | Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks aga... |
| CVE-2021-3115 | HIGH | 7.5 | 6.4% | Jan 26, 2021 | Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when ... |
| CVE-2021-3114 | MEDIUM | 6.5 | 2.7% | Jan 26, 2021 | In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect outputs, related to an und... |
| CVE-2021-26267 | HIGH | 7.5 | 0.9% | Jan 26, 2021 | cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579). |
| CVE-2021-26266 | HIGH | 7.5 | 0.9% | Jan 26, 2021 | cPanel before 92.0.9 allows a Reseller to bypass the suspension lock (SEC-578). |
| CVE-2021-26026 | HIGH | 7.8 | 0.7% | Jan 26, 2021 | PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDS... |
| CVE-2021-26025 | HIGH | 7.8 | 0.7% | Jan 26, 2021 | PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDS... |
| CVE-2021-25908 | HIGH | 7.5 | 1.3% | Jan 26, 2021 | An issue was discovered in the fil-ocl crate through 2021-01-04 for Rust. From<EventList> can lead to a double free. |
| CVE-2021-25907 | CRITICAL | 9.8 | 1.6% | Jan 26, 2021 | An issue was discovered in the containers crate before 0.9.11 for Rust. When a panic occurs, a util::{mutate,mutate2} do... |
| CVE-2021-25906 | HIGH | 7.5 | 1.3% | Jan 26, 2021 | An issue was discovered in the basic_dsp_matrix crate before 0.9.2 for Rust. When a TransformContent panic occurs, a dou... |
| CVE-2021-25905 | CRITICAL | 9.1 | 1.6% | Jan 26, 2021 | An issue was discovered in the bra crate before 0.1.1 for Rust. It lacks soundness because it can read uninitialized mem... |
| CVE-2021-25904 | HIGH | 7.5 | 1.3% | Jan 26, 2021 | An issue was discovered in the av-data crate before 0.3.0 for Rust. A raw pointer is dereferenced, leading to a read of ... |
| CVE-2021-25903 | HIGH | 7.5 | 1.4% | Jan 26, 2021 | An issue was discovered in the cache crate through 2021-01-01 for Rust. A raw pointer is dereferenced. |
| CVE-2021-25902 | HIGH | 7.5 | 1.4% | Jan 26, 2021 | An issue was discovered in the glsl-layout crate before 0.4.0 for Rust. When a panic occurs, map_array can perform a dou... |
| CVE-2021-25901 | MEDIUM | 5.3 | 1.3% | Jan 26, 2021 | An issue was discovered in the lazy-init crate through 2021-01-17 for Rust. Lazy lacks a Send bound, leading to a data r... |
| CVE-2021-25900 | CRITICAL | 9.8 | 1.7% | Jan 26, 2021 | An issue was discovered in the smallvec crate before 0.6.14 and 1.x before 1.6.1 for Rust. There is a heap-based buffer ... |
| CVE-2021-25864 | HIGH | 7.5 | 9.3% | Jan 26, 2021 | node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in fil... |
| CVE-2021-25863 | HIGH | 8.8 | 1.2% | Jan 26, 2021 | Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account. |
| CVE-2021-22873 | MEDIUM | 6.1 | 66.1% | Jan 26, 2021 | Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg... |
| CVE-2021-22872 | MEDIUM | 6.1 | 3.4% | Jan 26, 2021 | Revive Adserver before 5.1.0 is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the publicly acce... |
| CVE-2021-22871 | MEDIUM | 4.8 | 2.1% | Jan 26, 2021 | Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL webs... |
| CVE-2021-22698 | HIGH | 7.8 | 3.9% | Jan 26, 2021 | A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody... |
| CVE-2021-22697 | HIGH | 7.8 | 3.5% | Jan 26, 2021 | A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody... |
| CVE-2021-21723 | HIGH | 7.5 | 1.2% | Jan 26, 2021 | Some ZTE products have a DoS vulnerability. Due to the improper handling of memory release in some specific scenarios, a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now